gecko/security/insanity/lib/pkixder.cpp
Brian Smith d9de262bc3 Bug 921887: Add minimal DER decoder to insanity::pkix, r=keeler
--HG--
extra : rebase_source : 12becc63c3f1d4f04f0164d236b6759e9f4e81cc
extra : source : 6db5ba057f8d557eaf238d35d539e4c3dc08be1a
2013-09-29 12:08:33 -07:00

82 lines
2.2 KiB
C++

/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
/* vim: set ts=8 sts=2 et sw=2 tw=80: */
/* Copyright 2013 Mozilla Foundation
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
#include "pkixder.h"
namespace insanity { namespace der {
// not inline
Result
Fail(PRErrorCode errorCode)
{
PR_SetError(errorCode, 0);
return Failure;
}
// Too complicated to be inline
Result
ExpectTagAndGetLength(Input& input, uint8_t expectedTag, uint16_t& length)
{
PR_ASSERT((expectedTag & 0x1F) != 0x1F); // high tag number form not allowed
uint8_t tag;
if (input.Read(tag) != Success) {
return Failure;
}
if (tag != expectedTag) {
return Fail(SEC_ERROR_BAD_DER);
}
// The short form of length is a single byte with the high order bit set
// to zero. The long form of length is one byte with the high order bit
// set, followed by N bytes, where N is encoded in the lowest 7 bits of
// the first byte.
uint8_t length1;
if (input.Read(length1) != Success) {
return Failure;
}
if (!(length1 & 0x80)) {
length = length1;
} else if (length1 == 0x81) {
uint8_t length2;
if (input.Read(length2) != Success) {
return Failure;
}
if (length2 < 128) {
// Not shortest possible encoding
return Fail(SEC_ERROR_BAD_DER);
}
length = length2;
} else if (length1 == 0x82) {
if (input.Read(length) != Success) {
return Failure;
}
if (length < 256) {
// Not shortest possible encoding
return Fail(SEC_ERROR_BAD_DER);
}
} else {
// We don't support lengths larger than 2^16 - 1.
return Fail(SEC_ERROR_BAD_DER);
}
return Success;
}
} } // namespace insanity::der